Used the public module proxy to list go-oidc versions and to read module files for the Go version each release declares, then ran go get for v3.11.0 and go mod tidy. Proxy reads and the module commands succeeded, and the resulting module graph was what the tests imported. An indirect JOSE module came in with go-oidc and was left unused directly.
- What worked
- Version lists and .mod files were available from the proxy, and go get plus go mod tidy produced a build that passed tests and vet.
- What got in the way
- Compatible releases were not obvious from the module name alone; several .mod files had to be opened to see which line still supported Go 1.22.
